ExamplesTemplates

E2B Kata

The same sandbox in its own kernel — a microVM runtime class, for code you do not trust.

Source

config/samples/e2b-kata_sandboxtemplate.yaml on the develop branch — the file this page is rendered from, and the one to apply.

The same sandbox as e2b-basic_sandboxtemplate.yaml, with one line that matters: runtimeClassName, which asks the cluster to run the Pod in its own kernel (Kata Containers, Firecracker, or whatever your cluster publishes) instead of sharing the node's. A container escape from a shared-kernel Pod lands on the node; from here it lands in a virtual machine.

kubectl apply -f config/samples/e2b-kata_sandboxtemplate.yaml

Two things to check before you use it:

  • the class exists: kubectl get runtimeclass. The name below is the conventional one; use whatever yours is called, or the Pod never schedules.
  • the runtime has the RAM: a microVM carries its own kernel, so a sandbox that fits in 2Gi on runc may want more here.

Cost is the other half of the trade: start-up is slower and each sandbox occupies more than a container would. Pay it where the code is untrusted — evaluations of a model you do not control, agents given a shell and a network. Every image below is public, like the other examples.

apiVersion: agents.navix.sh/v1alpha1
kind: SandboxTemplate
metadata:
  name: e2b-envd-kata
spec:
  version: 0.0.1
  description: E2B-compatible sandbox in a microVM — envd on a runtime class with its own kernel.
  idleImage: ghcr.io/scitix/agent-sandbox-idle:0.0.10
  runtimes:
    - name: envd
      port: 49983
      protocol: TCP
      description: E2B envd runtime
      readinessProbe:
        httpGet:
          port: 49983
          path: /health
  template:
    spec:
      # The whole difference from the basic template. Set this to the class
      # `kubectl get runtimeclass` shows on your cluster.
      runtimeClassName: kata-fc
      automountServiceAccountToken: false
      enableServiceLinks: false
      shareProcessNamespace: false
      containers:
        - name: sandbox
          image: ghcr.io/scitix/agent-sandbox-envd:0.9.0-2
          imagePullPolicy: IfNotPresent
          command:
            - /mnt/agentbox/tini
            - -g
            - --
            - /bin/sh
            - /mnt/agentbox/agentbox-entrypoint.sh
          env:
            - name: AGENTBOX_DIR
              value: /mnt/agentbox
            - name: PORT
              value: "49999"
          ports:
            - containerPort: 49983
              name: envd
              protocol: TCP
            - containerPort: 49999
              name: app
              protocol: TCP
          # More headroom than the basic template on purpose: the guest kernel
          # and its own page cache live inside these numbers.
          resources:
            limits:
              cpu: "1"
              memory: 4Gi
            requests:
              cpu: "1"
              memory: 4Gi
          securityContext:
            runAsGroup: 0
            runAsUser: 0
          volumeMounts:
            - mountPath: /mnt/agentbox
              name: shared-bin
              readOnly: true
      initContainers:
        - name: tini-injector
          image: ghcr.io/scitix/agent-sandbox-tini:v0.19.0-static
          imagePullPolicy: IfNotPresent
          command: [sh, -c]
          args:
            - |
              TARGET_DIR="/mnt/agentbox"
              mkdir -p "$TARGET_DIR"
              if [ -f "$TARGET_DIR/tini" ]; then
                  echo "[Init] tini already exists at $TARGET_DIR. Skipping copy."
              else
                  cp /workspace/tini "$TARGET_DIR/tini"
                  chmod +x "$TARGET_DIR/tini"
                  echo "[Init] tini static injected successfully."
              fi
          volumeMounts:
            - name: shared-bin
              mountPath: /mnt/agentbox
        - name: envd-injector
          image: ghcr.io/scitix/agent-sandbox-envd:0.9.0-2
          imagePullPolicy: IfNotPresent
          command: [sh, -c]
          args:
            - |
              TARGET_DIR="/mnt/agentbox"
              mkdir -p "$TARGET_DIR"
              if [ -f "$TARGET_DIR/envd" ] && [ -f "$TARGET_DIR/agentbox-entrypoint.sh" ]; then
                  echo "[Init] envd and scripts already exist in $TARGET_DIR. Skipping copy."
              else
                  cp /workspace/envd "$TARGET_DIR/"
                  cp /workspace/agentbox-entrypoint.sh "$TARGET_DIR/"
                  chmod +x "$TARGET_DIR/envd" "$TARGET_DIR/agentbox-entrypoint.sh"
                  echo "[Init] envd & scripts successfully injected."
              fi
          volumeMounts:
            - name: shared-bin
              mountPath: /mnt/agentbox
      volumes:
        - name: shared-bin
          emptyDir: {}
kubectl apply -f config/samples/e2b-kata_sandboxtemplate.yaml